CVE Explorer
CVE-2026-9516
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.
To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback that croaks, the restore is skipped and the scalar is left with its string pointer offset into its ow
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-763","description":"CWE-763 Release of Invalid Pointer or Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-755","description":"CWE-755 Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Cpanel-JSON-XS","product":"Cpanel::JSON::XS","programFiles":["XS.xs"],"programRoutines":[{"name":"decode_json"}],"repo":"https://github.com/rurban/Cpanel-JSON-XS","vendor":"RURBAN","versions":[{"lessThan":"4.41","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-763","description":"CWE-763 Release of Invalid Pointer or Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-755","description":"CWE-755 Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/06/03/5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/rurban/Cpanel-JSON-XS/commit/dfe1b41a36caba51dc12a2917fe50285d1ffaa7b.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/references/0
{"tags":["release-notes"],"url":"https://metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.41/changes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4dcde2a77ad22d6b71690bda9c33b6520dc12f38e5ae098b5956a7777ccf4c1e · sha256:c9ae38406488ea30… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.